Summary
- Make UK says 30% of manufacturers experienced a cyber incident directly or through their supply chain during the past year.
- Production downtime and higher operating costs were the most common consequences where incidents caused disruption.
- Only around half of manufacturers have incident-response plans, while almost a third lack cyber insurance or do not know whether they are covered.
Make UK says cyber incidents are moving beyond compromised accounts and inaccessible files into factory production, operating costs, and customer deliveries, as connected machinery and digitally integrated supply chains create more routes for an attack to interrupt physical work.
The manufacturing organisation’s latest Cyber Security in Manufacturing report found that 30% of UK manufacturers experienced a cyber incident during the past year, either directly or through their supply chain. Where an incident caused disruption, production downtime and increased operating costs were the most common consequences, while 31% of businesses affected by a supplier attack reported delays to customer deliveries.
Those figures turn cyber exposure into an industrial performance problem rather than a technical risk sitting beside the production line. Modern factories depend on combinations of enterprise software, connected equipment, remote access, suppliers, robotics, operational technology, and logistics systems, so an interruption in one digital component can halt work that still ends with a physical product leaving the site.
Make UK’s findings also expose a gap between that dependency and preparedness. Only around half of manufacturers have an incident-response plan, while almost a third either do not have cyber insurance or are unsure whether they are covered, leaving a substantial part of the sector without clarity over how an attack would be managed or how some of its financial consequences might be absorbed.
Manufacturing makes recovery particularly difficult because availability can be as important as confidentiality. A compromised corporate system may create a data-protection problem, but an unavailable production system can stop equipment, prevent work orders from reaching a line, interrupt warehouse processes, or leave staff unable to confirm what should be produced and shipped.
Simply reconnecting machinery or restoring software quickly is not necessarily safe. Organisations need confidence that an attacker has been removed, credentials have been secured, and restored systems are trustworthy before bringing critical processes back online, creating direct tension between containment and the commercial pressure to resume production.
Supplier dependence widens that problem because manufacturers rarely control every digital system on which output relies. Components, maintenance, software, transport, logistics, engineering services, and other specialist functions can sit across a network of organisations, while electronic ordering and production systems connect those companies closely enough that a disruption elsewhere can arrive as a missed delivery or stalled production schedule.
The 31% figure for customer delays following supplier cyber incidents is therefore particularly revealing. A business does not need to be breached itself to suffer the commercial effects of an attack; it only needs to depend on an organisation that can no longer deliver a component, operate a warehouse, process an order, or provide access to a required service.
Manufacturing adds the expense of idle physical assets to that third-party exposure. Factory equipment, skilled employees, energy, and facilities continue to carry costs while production is interrupted, making even a relatively short outage financially significant before remediation or data-loss costs are counted.
Operational technology introduces another complication because equipment designed to run reliably for many years does not always follow the replacement and patching cycles familiar in conventional IT. Manufacturers may also have machinery supplied and maintained by external engineering companies, dividing security responsibilities among internal technology teams, production staff, equipment vendors, and contractors.
Make UK is calling for board-level ownership of cyber risk alongside basic cyber hygiene, staff training, patch management, supplier assurance, protection for operational technology, and tested recovery plans. None is especially novel as security practice, but the production data gives them a clearer economic context: resilience determines whether a factory can keep making and delivering goods when a digital dependency fails.
Insurance can offset some financial losses, subject to terms and exclusions, but it cannot manufacture delayed components, restore lost production hours, or preserve customer relationships if orders repeatedly arrive late. The uncertainty reported by almost a third of manufacturers over whether they are covered also suggests that financial and operational risk management are not always connected.
As factories add automation, connected sensors, remote diagnostics, and data-driven production systems, keeping operational environments permanently isolated from the rest of the organisation becomes less realistic. The commercial advantages of connectivity depend on information moving between production, engineering, suppliers, and corporate systems.
The stronger measure is therefore whether failures can be contained when they occur. With nearly one in three manufacturers encountering an incident either directly or through suppliers and only around half holding response plans, the sector is already seeing cyber risk arrive as lost production and delayed orders before resilience practices have become equally widespread.












